The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of Ubuntu

vulnerability alert CVE-2017-12806

ImageMagick: denial of service via format8BIM

Synthesis of the vulnerability

An attacker can trigger a fatal error via format8BIM() of ImageMagick, in order to trigger a denial of service.
Impacted products: Fedora, openSUSE Leap, SUSE Linux Enterprise Desktop, SLES, Ubuntu.
Severity: 1/4.
Consequences: denial of service on service, denial of service on client.
Provenance: document.
Creation date: 26/06/2019.
Identifiers: CVE-2017-12806, FEDORA-2019-da4c20882c, openSUSE-SU-2019:1683-1, SUSE-SU-2019:1712-1, USN-4034-1, VIGILANCE-VUL-29621.

Description of the vulnerability

An attacker can trigger a fatal error via format8BIM() of ImageMagick, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

vulnerability CVE-2017-12805

ImageMagick: denial of service via ReadTIFFImage

Synthesis of the vulnerability

An attacker can trigger a fatal error via ReadTIFFImage() of ImageMagick, in order to trigger a denial of service.
Impacted products: Fedora, openSUSE Leap, SUSE Linux Enterprise Desktop, SLES, Ubuntu.
Severity: 1/4.
Consequences: denial of service on service, denial of service on client.
Provenance: document.
Creation date: 26/06/2019.
Identifiers: CVE-2017-12805, FEDORA-2019-da4c20882c, openSUSE-SU-2019:1683-1, SUSE-SU-2019:1712-1, USN-4034-1, VIGILANCE-VUL-29620.

Description of the vulnerability

An attacker can trigger a fatal error via ReadTIFFImage() of ImageMagick, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability alert CVE-2016-10321

web2py: information disclosure via Denied Host Brute Force

Synthesis of the vulnerability

An attacker can bypass access restrictions to data via Denied Host Brute Force of web2py, in order to obtain sensitive information.
Impacted products: Ubuntu.
Severity: 1/4.
Consequences: data reading.
Provenance: internet client.
Creation date: 24/06/2019.
Identifiers: CVE-2016-10321, USN-4030-1, VIGILANCE-VUL-29606.

Description of the vulnerability

An attacker can bypass access restrictions to data via Denied Host Brute Force of web2py, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability note 29569

Ubuntu: security improvement via Evince AppArmor Profile

Synthesis of the vulnerability

The security of Ubuntu was improved via Evince AppArmor Profile.
Impacted products: Ubuntu.
Severity: 1/4.
Consequences: no consequence.
Provenance: internet client.
Creation date: 20/06/2019.
Identifiers: USN-4024-1, VIGILANCE-VUL-29569.

Description of the vulnerability

This bulletin is about a security improvement.

It does not describe a vulnerability.

The security of Ubuntu was therefore improved via Evince AppArmor Profile.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability note CVE-2019-11815

Linux kernel: use after free via rds_tcp_kill_sock

Synthesis of the vulnerability

An attacker can force the usage of a freed memory area via rds_tcp_kill_sock() of the Linux kernel, in order to trigger a denial of service, and possibly to run code.
Impacted products: Debian, Linux, openSUSE Leap, SUSE Linux Enterprise Desktop, SLES, Ubuntu.
Severity: 1/4.
Consequences: administrator access/rights, privileged access/rights, user access/rights, denial of service on server, denial of service on service, denial of service on client.
Provenance: LAN.
Creation date: 09/05/2019.
Revision date: 24/05/2019.
Identifiers: CERTFR-2019-AVI-244, CERTFR-2019-AVI-254, CERTFR-2019-AVI-277, CVE-2019-11815, DLA-1824-1, DSA-4465-1, openSUSE-SU-2019:1404-1, openSUSE-SU-2019:1407-1, openSUSE-SU-2019:1479-1, SUSE-SU-2019:1527-1, SUSE-SU-2019:1529-1, SUSE-SU-2019:1530-1, SUSE-SU-2019:1532-1, SUSE-SU-2019:1534-1, SUSE-SU-2019:1535-1, SUSE-SU-2019:1536-1, SUSE-SU-2019:1550-1, USN-4005-1, USN-4008-1, USN-4008-3, USN-4068-1, USN-4068-2, VIGILANCE-VUL-29259.

Description of the vulnerability

An attacker can force the usage of a freed memory area via rds_tcp_kill_sock() of the Linux kernel, in order to trigger a denial of service, and possibly to run code.
Full Vigil@nce bulletin... (Free trial)

vulnerability announce CVE-2019-5435 CVE-2019-5436

curl: multiple vulnerabilities

Synthesis of the vulnerability

An attacker can use several vulnerabilities of curl.
Impacted products: curl, Debian, Fedora, openSUSE Leap, Slackware, SUSE Linux Enterprise Desktop, SLES, Ubuntu.
Severity: 2/4.
Consequences: client access/rights, denial of service on client.
Provenance: intranet server.
Number of vulnerabilities in this bulletin: 2.
Creation date: 22/05/2019.
Identifiers: CVE-2019-5435, CVE-2019-5436, DLA-1804-1, FEDORA-2019-3f5b6f0f97, FEDORA-2019-697de0501f, openSUSE-SU-2019:1492-1, openSUSE-SU-2019:1508-1, SSA:2019-142-01, SUSE-SU-2019:1357-1, SUSE-SU-2019:1357-2, SUSE-SU-2019:1363-1, SUSE-SU-2019:14064-1, USN-3993-1, USN-3993-2, VIGILANCE-VUL-29382.

Description of the vulnerability

An attacker can use several vulnerabilities of curl.
Full Vigil@nce bulletin... (Free trial)

vulnerability CVE-2019-10131

GraphicsMagick: out-of-bounds memory reading via formatIPTCfromBuffer

Synthesis of the vulnerability

An attacker can force a read at an invalid address via formatIPTCfromBuffer() of GraphicsMagick, in order to trigger a denial of service, or to obtain sensitive information.
Impacted products: openSUSE Leap, SUSE Linux Enterprise Desktop, SLES, Ubuntu.
Severity: 1/4.
Consequences: data reading, denial of service on server, denial of service on service, denial of service on client.
Provenance: document.
Creation date: 22/05/2019.
Identifiers: CVE-2019-10131, openSUSE-SU-2019:1427-1, openSUSE-SU-2019:1683-1, SUSE-SU-2019:1712-1, USN-4034-1, VIGILANCE-VUL-29380.

Description of the vulnerability

An attacker can force a read at an invalid address via formatIPTCfromBuffer() of GraphicsMagick, in order to trigger a denial of service, or to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability note CVE-2019-11833

Linux kernel: information disclosure via ext4/extents.c

Synthesis of the vulnerability

A local attacker can read a memory fragment via ext4/extents.c of the Linux kernel, in order to obtain sensitive information.
Impacted products: Debian, Fedora, Linux, openSUSE Leap, SUSE Linux Enterprise Desktop, SLES, Ubuntu.
Severity: 1/4.
Consequences: data reading.
Provenance: privileged shell.
Creation date: 22/05/2019.
Identifiers: CERTFR-2019-AVI-277, CVE-2019-11833, DLA-1823-1, DLA-1824-1, DSA-4465-1, FEDORA-2019-48b34fc991, openSUSE-SU-2019:1479-1, openSUSE-SU-2019:1570-1, openSUSE-SU-2019:1579-1, SUSE-SU-2019:1527-1, SUSE-SU-2019:1529-1, SUSE-SU-2019:1530-1, SUSE-SU-2019:1532-1, SUSE-SU-2019:1533-1, SUSE-SU-2019:1534-1, SUSE-SU-2019:1535-1, SUSE-SU-2019:1536-1, SUSE-SU-2019:1550-1, SUSE-SU-2019:1692-1, USN-4068-1, USN-4068-2, USN-4069-1, VIGILANCE-VUL-29379.

Description of the vulnerability

A local attacker can read a memory fragment via ext4/extents.c of the Linux kernel, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

vulnerability bulletin CVE-2019-11460

gnome-desktop3: privilege escalation via TIOCSTI

Synthesis of the vulnerability

An attacker can bypass restrictions via TIOCSTI of gnome-desktop3, in order to escalate his privileges.
Impacted products: Fedora, Ubuntu.
Severity: 2/4.
Consequences: privileged access/rights, user access/rights.
Provenance: document.
Creation date: 20/05/2019.
Identifiers: CVE-2019-11460, FEDORA-2019-992622684b, USN-3994-1, VIGILANCE-VUL-29363.

Description of the vulnerability

An attacker can bypass restrictions via TIOCSTI of gnome-desktop3, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability announce CVE-2019-8595 CVE-2019-8607 CVE-2019-8615

WebKit2: three vulnerabilities

Synthesis of the vulnerability

An attacker can use several vulnerabilities of WebKit2.
Impacted products: iOS by Apple, iPhone, Mac OS X, Fedora, Ubuntu.
Severity: 2/4.
Consequences: unknown consequence, administrator access/rights, privileged access/rights, user access/rights, client access/rights, data reading, data creation/edition, data deletion, data flow, denial of service on server, denial of service on service, denial of service on client, disguisement.
Provenance: document.
Number of vulnerabilities in this bulletin: 3.
Creation date: 20/05/2019.
Identifiers: CVE-2019-8595, CVE-2019-8607, CVE-2019-8615, FEDORA-2019-f18fb0f37d, HT210118, USN-3992-1, VIGILANCE-VUL-29357.

Description of the vulnerability

An attacker can use several vulnerabilities of WebKit2.
Full Vigil@nce bulletin... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about Ubuntu: